WordPress Plugin Vulnerabilities

Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data

Description

The plugin does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.

Proof of Concept

Affects Plugins

References

Classification

Type
INJECTION
OWASP top 10

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-30 (about 2 days ago)
Added
2026-09-30 (about 1 day ago)
Last Updated
2026-10-01 (about 9 hours ago)

Other